Prototype Pollution Vulnerability in msgpack5 for Node.js and Browsers
CVE-2026-107301

6.5MEDIUM

Key Information:

Vendor

Mcollina

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107301?

The msgpack5 library, utilized for message packing in Node.js and browser environments, exhibits a prototype pollution vulnerability due to improper handling of options. Versions prior to 6.1.0 permit the creation of a decoded map that can include a proto key. This exploitation allows attackers to alter the prototype of decoded objects, potentially impacting inherited properties and behaviors within an application. It is crucial to upgrade to version 6.1.0 to mitigate this risk.

Affected Version(s)

msgpack5 < 6.1.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.